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The MAILING DATE of this communication appears on the cover sheet with the correspondence address - 
Period for Reply 



A SHORTENED STATUTORY PERIOD FOR REPLY IS SET TO EXPIRE 3 MONTH(S) OR THIRTY (30) DAYS, 
WHICHEVER IS LONGER, FROM THE MAILING DATE OF THIS COMMUNICATION. 

- Extensions of time may be available under the provisions of 37 CFR 1.136(a). In no event, however, may a reply be timely filed 
after SIX (6) MONTHS from the mailing date of this communication. . 

- If NO period for reply is specified above, the maximum statutory period will apply and will expire SIX (6) MONTHS from the mailing date of this communication. 

- Failure to reply within the set or extended period for reply will, by statute, cause the application to become ABANDONED (35 U.S.C. § 133). 
Any reply received by the Office later than three months after t he mailing date of this communication, even if timely filed, may reduce'any 
earned patent term adjustment. See 37 CFR 1.704(b). 

Status 

1)S Responsive to communication(s) filed on 11 March 2004 . 
2a)D This action is FINAL. 2b)E3 This action is non-final. 

3) D Since this application is in condition for allowance except for formal matters, prosecution as to the merits is 

closed in accordance with the practice under Ex parte Quayle, 1935 CD. 11, 453 O.G. 213. 

Disposition of Claims 

4) E3 Claim(s) 1-20 is/are pending in the application. 

4a) Of the above claim(s) is/are withdrawn from consideration. 

5) Q Claim(s) is/are allowed. 

6) 03 Claim(s) 1-20 is/are rejected. 

7) D Claim(s) is/are objected to. 

8) D Claim(s) are subject to restriction and/or election requirement. 

Application Papers 

9) D The specification is objected to by the Examiner. 

10)^ The drawing(s) filed on 11 March 2004 is/are: a)|3 accepted or b)D objected to by the Examiner. 

Applicant may not request that any objection to the drawing(s) be held in abeyance. See 37 CFR 1.85(a). 

Replacement drawing sheet(s) including the correction is required if the drawing(s) is objected to. See 37 CFR 1.121(d). 
1 !)□ The oath or declaration is objected to by the Examiner. Note the attached Office Action or form PTO-152. 

Priority under 35 U.S.C. § 119 

12)D Acknowledgment is made of a claim for foreign priority under 35 U.S.C. § 1 19(a)-(d) or (f). 
a)D All b)D Some * c)D None of: 

1 .□ Certified copies of the priority documents have been received. 

2. D Certified copies of the priority documents have been received in Application No. . 

3. D Copies of the certified copies of the priority documents have been received in this National Stage 

application from the International Bureau (PCT Rule 17.2(a)). 
* See the attached detailed Office action for a list of the certified copies not received. 
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DETAILED ACTION 

1. Claims 1-20 have been examined. 

Claim Rejections - 35 USC § 101 

2. 35 U.S. C. 101 reads as follows: 

Whoever invents or discovers any new and useful process, machine, manufacture, or composition of 
matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the 
conditions and requirements of this title. 

3. Claims 1 1-15 are rejected under 35 U.S.C. 101 because the claimed invention is 
directed to non-statutory subject matter. 

With respect to claims 11-15, the instruction is embodied on "a signal-bearing 
medium". This subject matter is not limited to that which falls within a statutory category 
of invention because it is not limited to a process, machine, manufacture, or a 
composition of matter. Instead, it includes a form of energy. Energy does not fall within 
a statutory category since it is clearly not a series of steps or acts to constitute a 
process, not a mechanical device or combination of mechanical devices to constitute a 
machine, not a tangible physical article or object which is some form of matter to be a 
product and constitute a manufacture, and not a composition of two or more substances 
to constitute a composition of matter. 

Claim Rejections - 35 USC §112 

4. . The following is a quotation of the second paragraph of 35 U.S.C. 112: 

The specification shall conclude with one or more claims particularly pointing out and distinctly 
claiming the subject matter which the applicant regards as his invention. 
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5. Claim 5 is rejected under 35 U.S.C. 112, second paragraph, as being indefinite 
for failing to particularly point out and distinctly claim the subject matter which applicant 
regards as the invention. 

As per claim 5, "a second password" is being recited. Since there is no first 
password in the claim, "a second password" is undefined. It appears to the examiner "a 
second password" is a different password, however, the additional limitation "..that was 
previously used outside the set of pages" appears to be it is the same password. 

Claim Rejections - 35 USC § 102 

6. The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country or in public 
use or on sale in this country, more than one year prior to the date of application for patent in the United 
States. 

7. Claims 1-3, 6-8, 11-13 and 16-18 are rejected under 35 U.S.C. 102(b) as being 
anticipated by Child et al. (U.S. Patent No. 6,341,352). 

As per claim 1, Child et al. discloses a method, comprising: 
determining whether a password is restricted to a set of pages ("..the Web server then 
invokes a server path check at step 72. The PathCheck function checks with the 
session manager to determine whether the user has appropriate DCE credentials. If so, 
the routine continues at step 74 to determine whether the user's password has expired. 
This step is also preferably performed during the PathCheck function" - e.g. col. 6, lines 
35-41 . Please note an expired password corresponds to Applicant's password is 
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restricted) and if the determining is true, denying submission of the password outside 
the set of pages ("In particular, whenever the user's password has expired, it is 
desirable according to the present invention to suspend a given Web transaction 
request." - e.g. col. 6, lines 10-12). 

As per claim 2, Child et al. discloses a method as applied above in claim 1. 
Child et al. further discloses wherein the set of pages comprises all pages within a 
domain ("...a Web client to obtain access to files stored in a distributed file system 
space of a distributed computing environment" - e.g. abstract and "...Web browser 
accesses Web documents stored in a secure distributed file system space" - e.g. col. 
2, lines 24-25 and col. 5, lines 4-19. Please note files/Web documents correspond to 
Applicant's all pages). 

As per claim 3, Child et al. discloses a method as applied above in claim 1 . 
Child et al. further discloses wherein the set of pages comprises a single page ("...a 
Web server application that access a document within the file system space on behalf 
of the Web browser user" - e.g. col. 2, lines 34-36. Please note a document 
corresponds to Applicant's a single page). 

As per claims 6, 11 and 16, Child et al. discloses an 
apparatus/instructions/system comprising: means for determining whether a password 
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is restricted to a set of pages ("..the Web server then invokes a server path check at 
step 72. The PathCheck function checks with the session manager to determine 
whether the user has appropriate DCE credentials. If so, the routine continues at step 
74 to determine whether the user's password has expired. This step is also preferably 
performed during the PathCheck function" - e.g. col. 6, lines 35-41. Please note an 
expired password corresponds to Applicant's password is restricted); means for 
denying submission of the password outside the set of pages if the determining is true 
("In particular, whenever the user's password has expired, it is desirable according to 
the present invention to suspend a given Web transaction request ." - e.g. col. 6, lines 
10-12); and means for allowing submission of the password outside the set of pages if 
the determining is false ("...If the outcome of the test at step 74 is negative, the routine 
branches to step 76 and completes the transaction processing as has been previously 
described" - e.g. col. 6, lines 29-44). 

As per claims 7, 12 and 17, Child et al. further discloses wherein the set of 
pages comprises all pages within a domain "...a Web client to obtain access to files 
stored in a distributed file system space of a distributed computing environment" - e.g. 
abstract and "...Web browser accesses Web documents stored in a secure distributed 
file system space" - e.g. col. 2, lines 24-25 and col. 5, lines 4-19. Please note files/web 
documents correspond to Applicant's all pages). 

As per claims 8, 13 and 18, Child et al. further discloses wherein the set of 
pages comprises a single page ("...a Web server application that access a document 
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within the file system space on behalf of the Web browser user" - e.g. col. 2, lines 34- 
36. Please note a document corresponds to Applicant's a single page). 

Claim Rejections • 35 USC § 103 

8. The following is a quotation of 35 U.S. C. 1 03(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 1 02 of this title, if the differences between the subject matter sought to be patented and 
the prior art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

9. The factual inquiries set forth in Graham v. John Deere Co., 383 U.S. 1 , 148 
USPQ 459 (1966), that are applied for establishing a background for determining 
obviousness under 35 U.S.C. 103(a) are summarized as follows: 

1 . Determining the scope and contents of the prior art. 

2. Ascertaining the differences between the prior art and the claims at issue. 

3. Resolving the level of ordinary skill in the pertinent art. 

4. Considering objective evidence present in the application indicating 
obviousness or nonobviousness. 

10. This application currently names joint inventors. In considering patentability of 
the claims under 35 U.S.C. 103(a), the examiner presumes that the subject matter of 
the various claims was commonly owned at the time any inventions covered therein 
were made absent any evidence to the contrary. Applicant is advised of the obligation 
under 37 CFR 1 .56 to point out the inventor and invention dates of each claim that was 
not commonly owned at the time a later invention was made in order for the examiner to 
consider the applicability of 35 U.S.C. 103(c) and potential 35 U.S.C. 102(e), (f) or (g) 
prior art under 35 U.S.C. 103(a). 
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11. Claims 4-5, 9-10, 14-15 and 19-20 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Child et al. (U.S. Patent No. 6,341,352). 

As per claims 4, 9, 14 and 19, Child et al. does not expressly disclose one page 
comprises password restriction control information. 

However, Child et al. discloses in col. 3, lines 4-5, "...a determination is made 
regarding whether the user's password has expired" and in col. 3, lines 37-39, "..a 
determination is made regarding whether a revised security policy for the application 
exists" and in col. 1, lines 18-31, "...via a standard page description language known as 
Hypertext Markup language (HTML). HTML provides basic document formatting and 
allows the developer to specify "links" to other server and files... In response, the client 
makes a request to the server identified in the link and receives in return a document 
formatted, for example, according to HTML". Therefore, it would have been obvious to 
a person with ordinary skill in the art at the time of the invention that Child et al.'s 
expired password information/revised security policy for the application can exist in one 
page. 

The motivation of doing so would have been to "addressed the problem of 
managing password expiration (or other security policy changes) in a system wherein a 
user of Web browser access Web documents stored in a secure distributed file system 
space", as disclosed by Child et al. (col. 2, lines 22-25) 
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As per claims 5, 10, 15 and 20, Child et al. discloses submission of a second 
password inside the set of pages and denying submission of a second password inside 
the set of pages (e.g. fig. 5, col. 6, line 56 - col. 7, line 14) 

Child et al. does not expressly disclose the second password was previously 
used outside the set of pages and saving a restriction entered from a user interface. 

However, Child et al. discloses in col. 7, lines 11-14, "..if the user makes a 
mistake when changing his or her password, the DCE/DFS administration function 
preferably redisplays the panel with an error message". 

It would have been obvious to a person with ordinary skill in the art, a mistake 
can be the expired password the user submitted outside the set of pages. Also, the 
examiner takes official notice that saving a restriction entered from a user interface is 
common knowledge in the art at the time of the invention. 

The motivation of doing so would have been to "addressed the problem of 
managing password expiration (or other security policy changes) in a system wherein a 
user of Web browser access Web documents stored in a secure distributed file system 
space", as disclosed by Child et al. (col. 2, lines 22-25) 

Conclusion 

12. The prior art made of record and not relied upon is considered pertinent to 
applicant's disclosure. (See PTO-892). 
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Contact Information 



Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to April Y. Shan whose telephone number is (571 ) 270- 
1014 ; The examiner can normally be reached on Monday - Friday, 8:00 a.m. - 5:00 
p.m., EST. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Kim Y. Vu can be reached on (571) 272-3859. The fax phone number for 
the organization where this application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 



8 May 2007 
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